Server-Side Request Forgery Vulnerability in Amazon AWS Systems Manager Agent
CVE-2026-89049
8.5HIGH
What is CVE-2026-89049?
Amazon AWS Systems Manager Agent is vulnerable to a server-side request forgery issue due to improper validation of address representations in its port forwarding functionality. This vulnerability could allow an authenticated remote user to bypass the destination denylist and connect to link-local endpoints. By exploiting this flaw, attackers might gain unauthorized access to temporary IAM role credentials of a managed instance, enabling them to execute actions using the role's permissions from outside the instance. Users are advised to upgrade to version 3.3.4851.0 or later to mitigate this risk.
Affected Version(s)
Amazon SSM Agent 0 < 3.3.4851.0
